pre-test section infection method-->change entry point to the evil payload, for payload continue to parent process

BDF will automatically unsign a signed binary, OSX doesnt care its not signed, just that the signature is correct

interesting boot processes that were patchable
-/sbin/launchd - the first process
-/usr/libexec/xpcproxy - almost everything uses it
-/usr/bin/security
-/usr/bin/awk awk was a boot processlaunchd launches a script that launches awk